Privacy Policy
Effective date: 2026-06-28
Who we are
WeddingPlan (this site, at my.weddingplan.cc) is a music-first wedding planning app. WeddingPlan is a product of EasyAsst Software, a dba of TWICE AS DEEP LLC. This Privacy Policy explains what data we collect, why we collect it, and how we protect it.
Contact: support@easyasst.com.
What data we collect
From couples
- Names you and your partner provide (so the planner can address you correctly).
- Your wedding date, venue address, and event timezone (so the planner can show countdowns and timelines).
- Answers you provide to planning questions (vendor contacts, song selections, do-not-play lists, special requests, etc.).
- Files you upload (cover photos, custom audio, PDFs you attach to a section).
- Authentication: you sign in via a unique magic-link URL emailed to you by your wedding professional. We do not store passwords.
From wedding professionals (operators)
- Operator login token (used to authenticate to the operator dashboard).
- If you choose to connect Spotify: your Spotify user ID, display name, and OAuth refresh + access tokens. We use these tokens only to list your playlists and read playlist contents on your behalf. We never post to Spotify, modify your playlists, or access data outside the scopes you authorized.
Automatic technical data
- A session cookie on the operator dashboard (named
ws_operator_session). Couples authenticated by magic link do not set a session cookie. - Theme preference (light / dark / system) stored in your browser's localStorage.
- Standard web-server logs (IP address, user-agent, timestamps) retained for a short period for abuse-prevention purposes.
How we use your data
We use your data to provide the planner service: rendering your event, surfacing curated music recommendations, generating role-specific PDFs for your wedding team, and saving your work.
We do not sell your data. We do not run advertising on this app. We do not share your data with third parties except as needed to operate the service (for example, Supabase for database hosting, Railway for app hosting, Apple's iTunes Search API and Spotify's Web API for catalog data).
Music services
Spotify
When you (as an operator) connect your Spotify account, the app uses Spotify's Authorization Code OAuth flow with the playlist-read-private, playlist-read-collaborative, and user-read-private scopes. We store the resulting refresh token and a short-lived access token in our database so we can read your playlists. We do not use Spotify content for any purpose other than the explicit features described in this app (importing playlists as Recommendation crates and looking up individual tracks by URL).
You can disconnect Spotify at any time from the operator Settings page. Disconnecting deletes the stored tokens. Existing imported crates remain in the app; deleting them is a separate action.
All Spotify content displayed in the app (album art, artist names, track titles) is sourced from Spotify and remains subject to Spotify's Terms of Service and Branding Guidelines.
Apple Music / iTunes
We use the public iTunes Search API to look up song metadata, album art, and 30-second preview audio. No authentication is required for the catalog. Apple Music store links are surfaced as direct links to Apple's service when available.
Data retention
Couple-provided data (answers, songs, notes, uploads) is retained for as long as the associated event exists in the planner. When your wedding professional deletes an event, the associated data is deleted along with it.
Operator Spotify tokens are retained until the operator disconnects Spotify or deletes the connection record.
You can request deletion of any data at any time by emailing support@easyasst.com.
Security
Data in transit is encrypted via HTTPS. Database storage is hosted by Supabase with at-rest encryption. Operator authentication uses a shared secret token. Couple authentication uses unique magic links bound to a specific event.
No security is perfect. If you become aware of unauthorized access to your planner data, email support@easyasst.com immediately.
Your rights
You can request access to, correction of, or deletion of your data by emailing support@easyasst.com. We will respond within a reasonable timeframe (typically two weeks).
Children
WeddingPlan is intended for adults planning weddings. We do not knowingly collect personal information from anyone under age 16.
Changes to this policy
We may update this policy from time to time. The effective date at the top reflects the most recent revision. Material changes will be communicated via the operator dashboard.